Tar extraction in moby/go-archive can write outside the destination directory via link following
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 7.1epss 0.2%
de la publicación al arma0 días
Publicada en NVD18 ago
1ª PoC11 ago
probabilidad de explotación
0.2%top 91% de las CVE
explotación observada
noninguna fuente lo reporta
3 exploit(s) público(s)
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so links introduced by the archive can be followed out of the destination directory. An attacker who controls the contents of an archive can create or overwrite files at arbitrary paths writable by the extracting process.
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Docker · Docker CLIDocker · Docker ComposeDocker · Docker DesktopDocker · Docker EngineDocker · Docker Sandboxesmoby · go-archivePoCs públicas encontradas — 3
cve_referencegithub.com/masasron/CopyEscape-CVE-2026-17106★ 17githubgithub.com/HackSpeak/CVE-2026-17106★ 1githubgithub.com/686f6c61/POC-CopyEscape-CVE-2026-17106★ 1⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://docs.docker.com/desktop/release-notes/#4860https://docs.docker.com/engine/release-notes/29/#2970https://github.com/docker/cli/releases/tag/v29.7.0https://github.com/docker/compose/releases/tag/v5.4.0https://github.com/docker/sbx-releases/releases/tag/v0.38.0https://github.com/masasron/CopyEscape-CVE-2026-17106https://github.com/moby/go-archive/releases/tag/v0.3.0https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h